- Financial Technology (FinTech) providers are key to the structural enhancement of financial services during the Great Reset.
- Cybersecurity is critical to ensuring consumers and businesses can leverage the benefits of FinTech and bounce back from the crisis.
- The World Economic Forum’s FinTech Cybersecurity Consortium released recommendations for a common approach to cybersecurity controls.
The COVID-19 pandemic highlights the need to reduce the world’s reliance on central points in the financial system – facilitating value creation everywhere and supporting trade from periphery to periphery, not just from hub to hub.
And key to this structural enhancement of the financial system are Financial Technology, or FinTech, providers.
Trust and security are essential.
To help the economy bounce back from the COVID-19 crisis, citizens and small businesses need innovative ways to access financial services. And if new FinTech services are to be adopted at the speed necessary for economic recovery, citizens must be able to trust that the technologies are secure and that their assets are protected.
Cybersecurity, then, is essential to ensuring that consumers and businesses can leverage the benefits of FinTech.
The Challenge: Fragmentation
Cybersecurity is not a problem just for FinTechs. The FinTech revolution in financial services links organizations with varying degrees of cybersecurity maturity levels. The threat posed by cybercriminals and fraudsters creates shared risks across the financial system and must be managed collaboratively.
There are many approaches FinTechs can take to make themselves cybersecure. Yet it is not always clear which control frameworks best allow a FinTech to secure its assets, create trusted commercial partnerships with established firms and ensure compliance with relevant regulations in the jurisdictions in which it operates.
Established financial services providers have a number of frameworks, standards and industry-driven initiatives available to test the security of FinTechs and other third parties. However, the volume of industry initiatives – driven by the pace of technological change and the multiplication of regulations – is now creating “noise”. This makes it difficult for FinTechs to direct their resources in a way that allows for security while also facilitating commercial partnerships.
Requirements placed on FinTechs sow confusion, increase costs and may incentivise “security through obscurity”, in which less well-resourced firms play a game of chance, betting that they’re too small to be targeted by attackers and setting themselves up for problems in the future.
Have you read?
The Solution: Collaboration
The sector needs a mutually understood and widely accepted base level of cybersecurity controls. Clarity at the base level of security will support effective protection of business and client assets across the wider supply chain. This can accelerate the speed at which FinTechs can come to market and create commercial partnerships – and, in turn, incentivise good cyber hygiene and cybersecurity techniques among the least-resourced companies, improving cyber resilience systemwide.
Today, the World Economic Forum’s FinTech Cybersecurity Consortium released recommendations for a common approach to cybersecurity controls. This provides a pathway for the private sector and public agencies to build on existing control and assessment frameworks, such as the Center for Internet Security Critical Security Controls.
To support the implementation of these recommendations, the Forum has joined the Management Board of the Cyber Risk Institute, where it will provide input on the development and scaling of the Financial Services Cybersecurity Profile.
What is the World Economic Forum doing on cybersecurity
The World Economic Forum Platform for Shaping the Future of Cybersecurity and Digital Trust aims to spearhead global cooperation and collective responses to growing cyber challenges, ultimately to harness and safeguard the full benefits of the Fourth Industrial Revolution. The platform seeks to deliver impact through facilitating the creation of security-by-design and security-by-default solutions across industry sectors, developing policy frameworks where needed; encouraging broader cooperative arrangements and shaping global governance; building communities to successfully tackle cyber challenges across the public and private sectors; and impacting agenda setting, to elevate some of the most pressing issues.
Platform activities focus on three main challenges:
Strengthening Global Cooperation for Digital Trust and Security - to increase global cooperation between the public and private sectors in addressing key challenges to security and trust posed by a digital landscape currently lacking effective cooperation at legal and policy levels, effective market incentives, and cooperation between stakeholders at the operational level across the ecosystem.Securing Future Digital Networks and Technology - to identify cybersecurity challenges and opportunities posed by new technologies and accelerate solutions and incentives to ensure digital trust in the Fourth Industrial Revolution.Building Skills and Capabilities for the Digital Future - to coordinate and promote initiatives to address the global deficit in professional skills, effective leadership and adequate capabilities in the cyber domain.
The platform is working on a number of ongoing activities to meet these challenges. Current initiatives include our successful work with a range of public- and private-sector partners to develop a clear and coherent cybersecurity vision for the electricity industry in the form of Board Principles for managing cyber risk in the electricity ecosystem and a complete framework, created in collaboration with the Forum’s investment community, enabling investors to assess the security preparedness of target companies, contributing to raising internal cybersecurity awareness.
For more information, please contact us.
Where to start?
Low-maturity FinTechs need a common cybersecurity framework and assessment process, tiered according to cybersecurity maturity levels and provide guidance for companies on when they need to adopt and enhance cybersecurity controls as they grow.
The solution should start with baseline requirements for controls and assessment, but also provide increasingly complex controls as organizations develop and as their cybersecurity risk management requirements mature.
Controls require regular adaptation as technology, threats and business models change. They are granular, specific to the assets they are meant to protect, and may have a limited shelf life.
We recommend that these controls should be defined by financial services providers, where the expertise and funding can be deployed at speed, in consultation with cybersecurity experts from other sectors, governmental agencies and relevant civil-society organizations.
FinTechs have the potential to be the engines of innovation we need during the Great Reset. The findings of the World Economic Forum’s FinTech Cybersecurity Consortium provide a starting point on the path to a security management system to get them there.